Live data from Hacker News

O.mg Cable

shop.hak5.org

191–200 of 555 posts

Re: O.mg Cable

#191
post #137
post #95

Earlier quoted context omitted.

With growing car theft in the US I've been curious about implanting GPS trackers on my own older enthusiast vehicles. There appears to be many options on Amazon but I can't bring myself to trust any of them. Has anyone here gone down that road before?

-Wouldn't an airtag (or two...) fit the bill nicely? (Assuming even car thieves use iPhones there's some poetic justice to be served in their own smartphones bringing them down...)

I think the airtag might actually alert them that they are being tracked - the anti-stalker features built into the network will alert an iPhone user when an airtag they don't own is in the vicinity while moving and changing locations.

Re: O.mg Cable

#193
post #28

Earlier quoted context omitted.

There's no risk of jail for theft in Seattle. https://crosscut.com/2019/10/whats-seattle-doing-solve-its-s...

And people wonder why there is so much crime...

About half blame poverty/insufficient government handouts and excuse the theft.

About half blame not prosecuting crime.

But no one wonders. Everyone "knows".

Re: O.mg Cable

#194
post #129
post #96

Earlier quoted context omitted.

Probably “Project Phoenix”. If you ask any project team to come up with a project name they will probably pick ‘Project Phoenix’.

Because all project work is reviving something that has been done before?

Because projects start in the smouldering ruins of as-is, and their business case is mythical (and if you want to rise in this environment you’d better be flame-retardant).

Re: O.mg Cable

#195
post #129
post #96

Earlier quoted context omitted.

Probably “Project Phoenix”. If you ask any project team to come up with a project name they will probably pick ‘Project Phoenix’.

Because all project work is reviving something that has been done before?

No dude because it’s a badass name. If it’s super cool you get to name it “Operation Dark Phoenix” which is even more badass.

Re: O.mg Cable

#196
post #186

Who buys this stuff? Other things in the shop: > Screen Crab: This covert inline screen grabber sits between HDMI devices - like a computer and monitor, or console and television - to quietly capture screenshots. Perfect for sysadmins, pentesters and anyone wanting to record what's on a screen. > Shark Jack: This portable network attack tool is a pentesters best friend optimized for social engineering engagements and…

The same people that buy lockpicks buy these:

* enthusiasts

* professional security people (blue team, pentesters)

* criminals

in the last 2 cases, they buy them because it's cheaper than making it themself.

Re: O.mg Cable

#197

Earlier quoted context omitted.

They are really quite unlike us. And our sets of norms is, shall we say, somewhat different to theirs.

You are commenting on a forum full of people who build tools and technology for facebook and google and probably palintir and a thousand other facial recognition and thoughtcrime style systems.

There are probably some generalizable differences between software engineers who work for intelligence agencies vs private sector engineers. The most significant factor being that government engineers need to be able to get a security clearance and pass the attendant background checks and interviews. Most of the engineers I've worked with in the private sector probably couldn't pass these checks because of foreign nationality or recreational drug use. It's a virtual certainty that the need for a security clearance produces a strong selection effect. Not saying it makes the intelligence engineers better or worse just that I'm sure there are some significant differences.

Re: O.mg Cable

#198
post #186

Who buys this stuff? Other things in the shop: > Screen Crab: This covert inline screen grabber sits between HDMI devices - like a computer and monitor, or console and television - to quietly capture screenshots. Perfect for sysadmins, pentesters and anyone wanting to record what's on a screen. > Shark Jack: This portable network attack tool is a pentesters best friend optimized for social engineering engagements and…

Yes, penetration testers, red teams, blue teams, auditors, and a myriad of other security conscious roles take advantage of these tools.

> What prevents a malicious actor from buying and using these tools?

Nothing.

What prevents any actor from buying and using it maliciously? A significantly deeper question. I rather promote this.

Re: O.mg Cable

#199
post #44

See also: C-to-C charger cables with Bluetooth remote activated dual payloads: https://sneaktechnology.com/product/usbninja-custom-type-c-t... I easily modified mine to mimmic Apple Keyboard USB IDs to avoid notifications. Works great! Cellular GPS tracking car charger: https://www.amazon.com/Charger-Locator-Professional-Listenin... Cellular GPS tracking USB charger cable: https://www.ebay.com/itm/223990414124 I have…

Am I missing something? The worst thing the cable can do is send HID commands, and snoop on traffic between your USB-connectable device and PC?

USB has been littered with bugs. I never got why this didn't get more news coverage but at least it was possible to read memory from USB. Personally for me it's also a reason that I switched to USB-C that there are less people around with USB-C cables.

https://security.stackexchange.com/questions/118854/attacks-...

Re: O.mg Cable

#200
post #91

Earlier quoted context omitted.

I would expect nothing, because the security we put ourselves through is nowhere close to sophisticated enough to notice.

I'm pretty sure this would look kind of weird under xrays. They probably see thousands of cables and it'd be pretty easy to spot the difference.

The TSA agent making $25/hr who was formerly a line chef or retail worker or correctional officer or whatever is not sophisticated enough to tell the difference. Suspicious computer cables don't cause planes to fall out of the sky, and that's about all that agency even pretends to care about.
Post reply on HN